<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/csaf_se/10</id>
  <title>Most recent entries from csaf_se</title>
  <updated>2026-10-02T09:45:00.122679+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2026-251-04</id>
    <title>SEVD-2026-251-04 — Incorrect Implementation of Authentication Algorithm vulnerability on Modicon M580 and Modicon M580 Safety</title>
    <updated>2026-09-08T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of a vulnerability in its Modicon M580 and Modicon M580 Safety controllers. 
The Modicon M580 is an Ethernet-based Programmable Automation Controller (ePAC) designed for industrial digital transformation.
Failure to apply the remediations provided below may risk establishing an unauthenticated connection to Modicon M580 or M580 Safety controllers which could result in loss of confidentiality, integrity and availability of the PLC.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2026-251-04"/>
    <published>2026-09-08T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2026-251-03</id>
    <title>SEVD-2026-251-03 — Insufficiently Protected Credentials vulnerability on SCADAPack x70 Products</title>
    <updated>2026-09-08T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of a vulnerability in its SCADAPack x70 products. The SCADAPack 47x, SCADAPack 47xi, SCADAPack 47xd, SCADAPack 470R and SCADAPack 57x products are Remote Terminal Units that provide communication capabilities for remote monitoring and control. Failure to apply the mitigations provided below may increase the risk of unauthorized access to RTU configuration through the Secure Lock functionality, potentially resulting in a loss of confidentiality.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2026-251-03"/>
    <published>2026-09-08T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2026-251-02</id>
    <title>SEVD-2026-251-02 — Improper Neutralization of Special Elements used in an OS Command vulnerability on PowerLogic T300</title>
    <updated>2026-09-08T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of a vulnerability in the Head Unit (HU250) for the PowerLogic T300 RTU (Remote 
Terminal Unit) (formerly Easergy T300 RTU).  
The [PowerLogic T300 RTU](https://www.se.com/ww/en/product-range/62399-easergy-t300) is a modular platform for medium voltage and low voltage public distribution 
network management.  
Failure to apply the remediation provided below may risk privilege escalation, which could result in 
unauthorized takeover of the device.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2026-251-02"/>
    <published>2026-09-08T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2026-251-01</id>
    <title>SEVD-2026-251-01 — Multiple Vulnerabilities on EcoStruxure IT Data Center Expert</title>
    <updated>2026-09-08T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of its vulnerability in its EcoStruxure IT Data Center Expert product 
The EcoStruxure IT Data Center Expert product is a scalable monitoring software that collects, organizes,and distributes critical device information providing a comprehensive view of equipment. 
Failure to apply the remediation provided below may risk information disclosure and remote compromise of the offer which could result in disruption of operations and access to system data.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2026-251-01"/>
    <published>2026-09-08T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2024-317-02</id>
    <title>SEVD-2024-317-02 — Modicon Controllers M340 / Momentum / MC80 &amp; EcoStruxure™ Control Expert</title>
    <updated>2026-09-08T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of multiple vulnerabilities in its Modicon Controllers M340 / Momentum / MC80 / EcoStruxure™ Control Expert products. [Modicon PAC](https://www.se.com/ww/en/product-subcategory/3950-pac-programmable-automation-controllers/?filter=business-1-industrial-automation-and-control) products control and monitor industrial operations. [EcoStruxure™ Control Expert](https://www.se.com/ww/en/product-range/548-ecostruxure-control-expert-unity-pro/#overview) is the engineering application for Modicon Controllers. Failure to apply the provided remediations/mitigations below may risk unauthorized access to the controller, which could result in the possibility of denial of service and loss of confidentiality, integrity of the controller.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2024-317-02"/>
    <published>2024-11-12T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2024-044-01</id>
    <title>SEVD-2024-044-01 — EcoStruxure™ Control Expert, EcoStruxure™ Process Expert and Modicon M340, M580 and M580 Safety PLCs</title>
    <updated>2026-09-08T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of multiple vulnerabilities in its EcoStruxure™ Control Expert ,
EcoStruxure™ Process Expert and Modicon M340, M580 PLCs (Programmable Logic
Controllers).
Modicon PLCs control and monitor industrial operations. EcoStruxure™ Control Expert is the
common programming, debugging and operating software for Modicon PLCs. EcoStruxure™
Process Expert DCS is a single automation system to engineer, operate, and maintain an entire
plant Infrastructure.
Failure to apply the remediations provided below may risk unauthorized access to your PLC,
which could result in the possibility of denial of service and loss of confidentiality, integrity of the
controller.

Note regarding vulnerability details: The severity of vulnerabilities was calculated using the
CVSS Base metrics in version 3.1 (CVSS v3.1) without incorporating the Temporal and
Environmental metrics. Schneider Electric recommends that customers score the CVSS
Environmental metrics, which are specific to end-user organizations, and consider factors such
as the presence of mitigations in that environment. Environmental metrics may refine the
relative severity posed by the vulnerabilities described in this document within a customer’s 
environment</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2024-044-01"/>
    <published>2024-02-13T12:41:43+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2023-010-06</id>
    <title>SEVD-2023-010-06 — EcoStruxure™ Control Expert, EcoStruxure™ Process Expert and Modicon M340, M580 and M580 CPU Safety</title>
    <updated>2026-09-08T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of multiple vulnerabilities in its EcoStruxure™ Control Expert, Modicon M340, Momentum, MC80, M580 and M580 CPU Safety. The Modicon M580 are PAC and Safety PLCs with built-in Ethernet for process, high availability &amp; safety solutions. The Modicon M340 offers compactness, flexibility, scalability, and robustness for the process industry and a wide range of demanding automation applications. The Modicon MC80 provides optimized operation, withstanding extreme conditions with high reliability and performance. The Modicon Momentum supports control and distributed I/O system with 4 fundamental components that easily snap together in various combinations to form versatile control systems or sub-systems. EcoStruxure™ Control Expert is the common programming, debugging and operating software for Modicon PLCs (Programmable Logic Controllers) and PACs (Programmable Automation Controllers). Failure to apply the mitigations provided below may risk unauthorized access to your PLC, which could result in the possibility of denial of service and loss of confidentiality and integrity of the controller.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2023-010-06"/>
    <published>2023-01-10T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2019-134-11</id>
    <title>SEVD-2019-134-11 — Multiple Vulnerabilities in Modicon Controller Products</title>
    <updated>2026-09-08T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of multiple vulnerabilities in its Modicon Controller products. 
The [Modicon Programmable Automation controllers](https://www.se.com/ww/en/product-subcategory/3950-pac-programmable-automation-controllers/) are used for complex networked communication, display 
and control applications  
Failure to apply the mitigations or remediations provided below may risk execution of unsolicited command on 
the PLC which could result in a loss of availability of the controller.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2019-134-11"/>
    <published>2019-05-14T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2026-132-02</id>
    <title>SEVD-2026-132-02 — Insufficient Entropy vulnerability on Multiple Products</title>
    <updated>2026-08-25T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of a vulnerability in the following products: 
 The Easergy C5 is a scalable and interoperable bay controller, protection and merging unit for large and critical
infrastructure electrical distribution systems.
The Easergy MiCOM P30 is a family of multifunction protection and control relays designed for medium, high 
and extra high voltage electrical networks. 
The Easergy MiCOM P40 is a protection relay series for Medium Voltage, High Voltage and Extra High Voltage 
protection.  
The Easergy MiCOM C264 is a modular and compact substation or bay controller, smart RTU and MV one box 
solution 
The EcoStruxure™ Power Automation System Gateway (EPAS=GTW) is a scalable, interoperable, and 
rugged communication gateway that helps to remotely monitor and operate electrical processes 
The EcoStruxure Power Automation System User Interface (EPAS-UI) product is an HMI SCADA designed for 
electrical networks and substations operations. 
The EcoStruxure Power Automation System Intelligent Power Management System and Fast Load Shedding
(iPMFLS) is a range of solutions designed to overcome size and performances constraints. 
 The EcoStruxure™ Power Operation (EPO) are an on-premises software offers that provides a single platform 
to monitor and control medium and lower power systems. 
The PowerLogic™ P5 is a medium voltage protection relay. 
The PowerLogic™ P7 is a protection and control platform designed for complex and advanced electrical 
network a…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2026-132-02"/>
    <published>2026-05-12T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2026-223-02</id>
    <title>SEVD-2026-223-02 — Multiple Vulnerabilities on NetBotz 5 750/755 Products</title>
    <updated>2026-08-11T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of multiple vulnerabilities in its NetBotz 5 – 750/755 products.The NetBotz 5 – 750/755 products are security and environmental monitors providing temperature, humidity, leak, smoke, vibration, door contact, and video monitoring capabilities.Failure to apply the remediation provided below may risk arbitrary or remote code execution over the local network, which could result in device manipulation and unauthorized data access.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2026-223-02"/>
    <published>2026-08-11T07:00:00+00:00</published>
  </entry>
</feed>
